Skip to main content
Cromo derives permissions from a person’s role in the active Workspace. Access to Project-scoped content also requires membership in that Project. Roles are cumulative: each role includes the capabilities of the role before it.

Role summary

Viewer

Use Viewer for people who need to ask questions, inspect Project context, and monitor operations without changing shared assets. A Viewer can:
  • use the assistant;
  • read Sources, Knowledge, Data, Dashboards, Workflows, connectors, members, settings, and billing information.

Member

Use Member for regular contributors and operators. In addition to Viewer access, a Member can:
  • add, change, review, and delete Sources and Knowledge;
  • create, update, and delete Data;
  • create, publish, and execute Dashboards;
  • create, execute, and approve Skills and Workflows;
  • use approved connectors.

Admin

Use Admin for people who manage access and configuration. In addition to Member access, an Admin can:
  • delete Dashboards;
  • manage connectors;
  • add or remove Project members;
  • manage Project settings;
  • manage Workspace members, roles, and settings.
Admins can view billing but cannot manage it.

Owner

An Owner has every Cromo permission, including billing management. Keep at least one active Owner in the Workspace. Limit the role to people who are responsible for the Workspace as a whole.

Project membership

A Workspace role does not automatically grant access to every Project. The user must also be a member of the Project for Project-scoped permissions to apply. An Admin or Owner can add an existing Workspace member to a Project. Removing a user from a Project does not remove their Workspace membership.

Apply least privilege

  • Use Viewer for read-only stakeholders.
  • Use Member for everyday contributors.
  • Use Admin only for people managing access, settings, or connector credentials.
  • Use Owner only where billing and full Workspace control are required.
  • Review membership when ownership or employment changes.
  • Pause owner-dependent Workflows before removing their owner from a Project.